The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Microsoft Security Bulletin (MS01-016): Malformed WebDAV Request Can Cause IIS to Exhaust CPU Resources
Time: 15:03 EST/20:03 GMT | News Source: ActiveWin.com | Posted By: Robert Stein

WebDAV is an extension to the HTTP protocol that allows remote authoring and management of web content. In the Windows 2000 implementation of the protocol, IIS 5.0 performs initial processing of all WebDAV requests, then forwards the appropriate commands to the WebDAV process. However, a flaw exists in the way WebDAV handles a particular type of malformed request. If a stream of such requests were directed at an affected server, it would consume all CPU availability on the server.

Because the discoverer of this vulnerability has chosen to publish code to exploit this vulnerability before a patch could be developed, Microsoft has developed a workaround that can be used to defend against attack. Knowledge Base article Q241520 provides step-by-step instructions for changing the permissions on the .DLL that provides WebDAV services in order to effectively disable it on the machine. When a patch is available, we will re-release this bulletin and provide updated information.

Microsoft recommends that customers consider applying the workaround to any servers running IIS 5.0. Although this obviously includes web servers, other services, notably Exchange 2000, may also require that IIS 5.0 be enabled.

Write Comment
Return to News

  Displaying 576 through 576 of 576
Prev | First
  The time now is 12:00:15 AM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/26/2025 10:23:50 AM
https://moanio.com/video.php?id=1578
https://moanio.com/video.php?id=5915
https://moanio.com/video.php?id=1342
https://moanio.com/video.php?id=4827
https://moanio.com/video.php?id=4702
https://moanio.com/video.php?id=5597
https://moanio.com/video.php?id=5856
https://moanio.com/video.php?id=3348
https://moanio.com/video.php?id=4800
https://moanio.com/video.php?id=3668

Write Comment
Return to News
  Displaying 576 through 576 of 576
Prev | First
  The time now is 12:00:15 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *